AI’s Infrastructure Bill Is Coming Due
This week, the AI story got considerably less abstract.
We spent a lot of the last month talking about what increasingly capable agents are allowed to touch, who is responsible when they cross a boundary, and how quickly security assumptions stop working when software can act instead of merely answer. All of that still matters. But there is another bill arriving at the same time, and this one comes with power lines, gas turbines, server racks, cooling systems and a breathtaking amount of borrowed money.
The AI boom is becoming an infrastructure boom.
That matters even if you never train a model, never buy a GPU and have no idea what a token costs. The companies building this infrastructure are competing for electricity, memory, networking equipment, land and capital. Those costs eventually turn up somewhere: cloud bills, device prices, utility planning, software subscriptions, local taxes, or investor expectations that somebody has to satisfy.
There were also several stories this week with much simpler advice. If you run FortiMail, Cisco SD-WAN or a GitLab self-hosted AI Gateway, you have work to do. If someone calls your finance department sounding exactly like an executive and asks for an unusual transfer, the voice is no longer authentication. And if a secret ever made it into a public GitHub repository, deleting the file is not the same thing as revoking the secret.
So let’s do the urgent stuff first. Then we’ll get to the really expensive question.
Three security stories where “we patched it” is only half the answer
Fortinet’s FortiMail problem is the most awkward one because attackers are already exploiting CVE-2026-104286 and, as of the latest weekend checks, the fixed builds are still listed as upcoming.
The flaw combines path traversal with improper handling of a NULL character in FortiMail’s web interface. In normal human terms, the software is supposed to limit where a web request can place a file. A specially crafted request can get around that boundary and write a file somewhere the attacker chooses without logging in first. Fortinet rates it 9.8 out of 10 and says it has been exploited in the wild.
The affected branches include FortiMail 7.2, 7.4, 7.6 and 8.0 releases. Fortinet has named 7.4.9, 7.6.7 and 8.0.2 as fixed versions, but the advisory has continued to describe those builds as upcoming. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set October 4 as the federal remediation date.
That creates the irritating version of security advice where “install the patch” is absolutely correct and not yet possible. Fortinet’s interim guidance is to disable Identity Based Encryption or remove the management interface from the public internet and limit it to trusted networks. The company has also published indicators of compromise.
Closing the hole doesn’t tell you who used it yesterday
The second story is Cisco’s CVE-2026-76504, an authentication bypass in Catalyst SD-WAN Manager that attackers are also exploiting. Cisco has fixed builds available and says there is no workaround. More importantly, Cisco tells administrators to preserve diagnostic bundles and have them checked for signs of compromise after upgrading.
That is exactly the right distinction. Patching changes what can happen next. It does not rewrite what already happened.
The same idea applies to GitLab’s self-hosted AI Gateway, although GitLab has not said this flaw is being exploited. CVE-2026-90970 can let an authenticated user with Duo Agent Platform access escape a prompt-template sandbox and execute operating-system commands on the gateway. GitLab has fixed 19.2.4, 19.3.2 and 19.4.1, and its hosted gateways have already been updated.
I like this one as a reminder that “the AI part” is not a separate security universe. A prompt template sounds like text. If the machinery evaluating that template can reach the host operating system, the prompt system is part of your application security boundary. Give text enough authority and, eventually, text becomes code with extra steps.
If you run any of these systems, the practical order is boring and effective: contain exposure, preserve useful evidence, patch when the fix exists, and then ask whether the machine was touched before you fixed it. Boring is underrated.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
A familiar voice is no longer a second factor
The most useful small-business security story this week may be the €95 million fraud at Fideuram, the private-banking arm of Intesa Sanpaolo.
According to Reuters and Corriere della Sera, the attack began with what appeared to be a WhatsApp message from a senior executive asking for urgent help with an overseas transaction. The fraudsters then followed with a phone call that appeared to come from a senior lawyer the bank chairman knew. The callers used AI to clone the lawyer’s voice, and emails that appeared to come from the law firm supplied beneficiary accounts.
The chairman believed the request was legitimate and instructed the finance department to move the money. Fideuram caught the fraud quickly enough to recover roughly €53 million. About €36 million remained missing in the reporting after funds moved through foreign accounts and cryptocurrency.
There is an uncomfortable correction here to advice I’ve given for years: “pick up the phone and verify” isn’t enough anymore.
The old idea behind out-of-band verification was that an attacker who controls email probably doesn’t control the phone call too. That assumption gets weaker when the attacker can imitate a familiar voice and steer the victim toward a number, callback or conversation the attacker controls.
The trusted channel has to exist before the emergency
The safer process is to verify unusual requests through a contact path you already trusted before the request arrived. Call the executive at the number in your directory. Use a known internal chat account. Require a second human approval for transfers above a meaningful threshold. If the request involves changing bank details, treat that as its own verification event instead of assuming the rest of the message makes it legitimate.
And do not use “but it sounded exactly like her” as evidence that the request is real. We have crossed that line.
This isn’t really an AI-security problem in the narrow sense. It’s a business-process problem made cheaper and more convincing by AI. The fraud works because a human being has legitimate authority to move money and the attacker creates enough believable context to borrow that authority for a few minutes.
That is why the defense belongs in the process, not in a training slide telling employees to listen harder for fake voices.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
The Big Story: AI’s infrastructure bill is coming due
Now we get to the story that I think matters beyond this week’s headlines.
PwC’s Global Data Centre Outlook projects $31.6 trillion in worldwide data center capital spending through 2050 under its central scenario. Annual spending rises from roughly $800 billion this year to $1.1 trillion in 2030 and $1.8 trillion by 2050.
Those are projections, not invoices already sitting on a desk. Forecasts that far out deserve a healthy amount of humility. But the structure of the spending is more interesting than the exact number.
A railroad is brutally expensive to build, but once the track is in the ground you don’t replace most of it every four years because a faster track came out. AI infrastructure is different. PwC estimates that servers, GPUs, storage and networking equipment will make up an increasing share of the total because that hardware has to be refreshed every few years. The report says information-and-communications equipment could grow from about 70% of data center capital spending now to 93% by 2050.
So this is not simply a construction boom. It is a construction boom with a recurring hardware subscription attached.
The money has to come from somewhere
Reuters sharpened the near-term problem this weekend. Bain estimates that hyperscalers and other companies building the infrastructure would need more than $4.2 trillion in new revenue over the next five years to support the planned investment. At the same time, broad productivity gains from AI are still difficult to see in U.S. economic data.
That doesn’t mean AI is a useless bubble. I use AI. Businesses are already finding real applications for it. Software development, research, customer support, fraud detection, accessibility, document processing and a dozen other areas can show very real gains.
But “this technology is useful” and “every dollar currently being spent on infrastructure will earn an acceptable return” are two completely different statements.
The internet was useful during the dot-com bubble. Railroads transformed economies while still bankrupting investors. Useful technologies can attract too much capital, too quickly, into the wrong projects. The underlying technology can win while plenty of individual bets lose.
That distinction is easy to miss because the AI debate keeps getting dragged toward absolutes. Either the models are about to remake civilization next Tuesday or the whole thing is autocomplete with venture capital. Reality can be much less tidy. AI can become a general-purpose technology while the financial assumptions surrounding this particular buildout turn out to be wildly optimistic.
The timing problem makes that harder. Cambridge economist Diane Coyle told Reuters that previous technological revolutions often took 10 to 50 years for productivity effects to work through the economy. Data center leases, debt payments and GPU refresh cycles do not operate on historical patience.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Electricity is turning into part of the product roadmap
Then there is power.
Earlier this week, Reuters reported that data center developers are increasingly buying smaller gas turbines and other behind-the-meter generation because they can be installed faster than waiting for major power plants or grid connections. The attraction is not that these systems are magically better. It is that a business can sometimes get them in two or three years instead of waiting considerably longer for larger infrastructure.
The tradeoff is cost and efficiency. Smaller systems can cost more per unit of electricity and, depending on the design, burn fuel less efficiently than large combined-cycle plants.
That is a remarkable change in the shape of the technology business. A software company used to worry about processors, networking and whether the database would survive Black Friday. Now the product roadmap can include turbines, substations, water rights and transmission queues.
Amazon’s announcement this week fits the same story from the community side. The company says it will put more than $1 billion over five years into communities around its U.S. data centers. It also says it will stop using nondisclosure agreements with government agencies on data center projects, publish annual energy and water metrics, and structure utility arrangements so its facilities pay for the infrastructure they require rather than shifting those costs onto local customers.
Those are Amazon’s promises. They aren’t proof that every project will avoid higher utility costs, water conflicts or local opposition. But the disclosure commitments matter because they make more of the promises testable.
If a company says its enormous new facility will not raise your electric bill, “show me the utility agreement” is a much more useful conversation than “trust us, we are very committed to the community.”
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Small businesses are downstream from the buildout
It is tempting to treat all of this as a fight among trillion-dollar companies. The consequences don’t stay there.
AI demand is already competing for memory chips and other components that also go into ordinary computers. Cloud providers have to recover infrastructure costs somewhere. Software companies paying more for inference have to decide whether to absorb that, raise prices, limit features or create another exciting subscription tier with a name nobody asked for.
Power is even broader. A data center that needs hundreds of megawatts lives on a real grid next to real businesses and households. If new generation and transmission are built for it, somebody finances those assets. If they are not built fast enough, other customers still live with the constraints.
So when you are budgeting laptops, cloud hosting, software or an automation project, you are not standing outside the AI economy just because your company has ten employees and no machine-learning team.
What I would not do is make long-term business decisions based on the assumption that today’s AI pricing is permanent. The market is subsidizing adoption, companies are still figuring out what users will pay for, hardware efficiency is changing quickly, and the capital structure underneath all of it is still moving.
Use the tools that create enough value to justify their actual cost. Keep exportable data. Avoid unnecessary lock-in. Don’t redesign a critical process around a feature that only makes economic sense if somebody else continues subsidizing it forever.
The interesting question is no longer whether AI can do useful work. It can.
The question is whether the useful work arrives at the same scale, and on the same schedule, as the infrastructure bill.
Custom application development
Off-the-shelf software is great when your business works the way the software expects. When it doesn’t, Raymond Tec builds focused internal tools, dashboards, portals, plugins, and custom applications around the work that actually needs to happen.
AI agents are pushing old permission models past their comfort zone
While the infrastructure gets bigger, the software is also getting more authority.
The Federal Trade Commission confirmed this week that it is investigating OpenAI, Anthropic and other AI developers over possible consumer risks from agents. California’s attorney general has also sent OpenAI an investigative subpoena over recent cybersecurity incidents. Those are investigations, not findings that the companies violated the law.
At almost the same time, Apple announced that it plans to tighten macOS Full Disk Access because AI agents make the old permission model harder to justify.
Full Disk Access was designed for software such as backup utilities that may genuinely need to read almost everything on a Mac. Apple now says the permission “largely sidesteps” its normal privacy protections and that some developers are using it in ways users may not fully understand. The company has not yet explained exactly what the replacement controls will look like, only that this level of access will require more explicit user action.
The interesting part is not whether Apple or the FTC has found the perfect answer. Neither has.
The interesting part is that the same design question has escaped the security-research lab and landed in product design and regulation: what does “permission” mean when the software receiving it can observe context, make a plan and take actions you did not spell out one by one?
“Allow access” needs a smaller blast radius
A backup program with Full Disk Access mostly does the thing you installed it to do: read files and copy them somewhere safe. An agent with Full Disk Access may use the same permission while also interpreting messages, deciding which files are relevant, calling outside services and taking actions based on what it finds.
That doesn’t make agents uniquely evil. It makes broad permissions more consequential.
This is the same reason Nvidia’s new agent tooling emphasizes deny-by-default network and filesystem rules, and why we keep coming back to scoped credentials and human approval. If an agent only needs to read one project folder, give it one project folder. If it needs to draft an email but not send one, separate those capabilities. If it needs access to production for one job, do not turn that into permanent ambient authority because the setup wizard made it convenient.
Good agent security is starting to look an awful lot like good computer security.
I consider that encouraging.
Reliable automation
Automation is wonderful until it quietly stops working three Tuesdays ago. Raymond Tec builds integrations with logging, monitoring, and failure handling in mind so the boring work stays automated without becoming mysterious.
Deleting a leaked secret is not revoking it
Truffle Security published one of the least glamorous and most useful security studies of the week.
The company examined a snapshot containing 224 million public GitHub repositories and found more than 1.1 million exposed credentials. Then it did the important part: it tested the candidates against the services that issued them. In late July, 543,699 still worked.
The repository snapshot itself finished crawling in August 2025, so this was not a count of credentials accidentally exposed for a few minutes last week. The median credential had been public for 784 days.
GitHub’s secret scanning and push protection help. Truffle found the default block cuts the exposure rate for credential formats it recognizes. But more than half of the still-live credentials were formats the default system did not recognize well enough to block.
And there is a simpler problem underneath all of it.
Detection is not revocation.
If an API key, token or password made it into a public repository, deleting the file does not make every copy of that credential disappear. Rewriting Git history does not call the provider and invalidate the key. Making the repository private does not reach into somebody else’s clone and remove it.
Treat a public secret as compromised. Revoke or rotate it at the service that issued it, replace it everywhere that legitimately needs the new value, and then clean the repository so you do not keep rediscovering the same mistake.
Microsoft’s new Digital Defense Report makes the same point from another angle. Attackers are using AI to move faster, but ordinary credentials and ordinary user execution still account for a large share of initial access. The tooling changes. The old mistakes keep paying rent.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
The first appellate AI copyright ruling is narrower than the headline
The Third Circuit has now published its full opinion in Thomson Reuters v. Ross Intelligence, giving us the reasoning behind the first U.S. appeals-court decision in the current wave of AI-training copyright cases.
Ross built a legal-research system and used thousands of Westlaw headnotes — short editorial summaries written by Thomson Reuters editors — to help create training material. The court held that 2,243 of those headnotes were sufficiently original to be protected by copyright and that Ross’s use was not fair use.
The court’s explanation is important because it also tells us what the case does not decide.
Ross was building a direct competitor to Westlaw. Its system was not generative AI; it returned passages from existing judicial opinions. The court found that Ross used the headnotes for a highly similar ultimate purpose, copied more than necessary when the underlying court opinions were freely available, and threatened a market in which Thomson Reuters already used or could license headnotes as AI training data.
This is precedent, not a universal answer
The opinion explicitly distinguishes Ross from cases involving generative models that can produce new expression. That does not mean those systems automatically qualify for fair use. It means this court said the questions are different.
So “appeals court rules AI training is copyright infringement” is too broad. “Appeals court says a company cannot copy a competitor’s editorial summaries to train a directly competing legal-search product under these facts” is a lot less dramatic and a lot closer to what happened.
The ruling still matters. It gives other courts a precedential appellate opinion discussing AI training, copyrightability, transformation and market harm. It also makes the facts around what was copied, what the model does and which market it competes in much harder to ignore.
That is probably where this entire area is headed anyway. There is not going to be one magical sentence declaring all AI training fair or all AI training illegal. The cases are going to turn on who copied what, why, how much, what the system produces and what market the copying affects.
Law is rude like that. It keeps wanting facts.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Something Good: trying to make dementia diagnosis take months instead of a year
UK Research and Innovation announced an £80 million Dementia Challenge this week that is putting nine different diagnostic and monitoring approaches into real NHS testing.
The headline goal is ambitious: by 2029, the program wants 92% of people referred for dementia assessment to receive a diagnosis within 18 weeks. UKRI says the current figure is around 60%, and some people wait more than a year.
The projects are refreshingly varied. One team is trying to cut an MRI brain scan from around 20 minutes to about seven. Another is testing a 15-minute remote cognitive assessment. There are blood-based biomarkers, home sensors, tools that track changes in memory and thinking, a system that looks at how the brain processes sound, and an AI clinical-decision tool that uses ordinary medical records, blood tests and cognitive tests to help predict progression.
That list also contains the part I like most about the program: none of these gets declared a breakthrough because it won a grant.
The technologies are going into real NHS settings, and only the approaches that demonstrate useful results get more funding. UKRI calls it a fail-fast model. In medicine, where a technically clever prototype can be a very long way from improving a patient’s day, that is a feature.
This is not a new dementia cure, and none of these tools is something a person should go demand from a doctor Monday morning because it appeared in a funding announcement. The positive story is more practical. Diagnosis itself is a bottleneck. If faster scans, accessible remote testing or better biomarkers can shorten that wait without sacrificing accuracy, people get more time to plan, reach treatment and support, and understand what is happening.
Sometimes the useful technology story is not that somebody invented a miracle.
It is that somebody is trying to make an awful process less awful.
What I’m watching next
The first thing I am watching next week is whether Fortinet ships the promised FortiMail builds and whether we learn anything more useful about the exploitation that happened before the fixes existed.
I also want to see what the FTC and California actually ask AI developers for. “We are investigating agent risk” is a headline. The document demands, testimony and eventual theory of responsibility will tell us what regulators think the practical boundaries should be.
And I am going to keep watching the infrastructure numbers. Not because I expect a giant AI bubble to pop at 2:17 on a Tuesday, and not because I think trillions of dollars automatically proves the spending is wise. The interesting part is the mismatch between physical buildout speed and the much slower work of finding applications that produce durable economic value.
AI keeps making software feel less physical.
The bill is becoming extremely physical.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
AI infrastructure, data centers and power
- Raymond Tec: Can AI Pay for Its Infrastructure? Plus 3 Stories
- Raymond Tec: Apple Patches an Exploited iPhone Flaw, Plus 3 Stories
- PwC: Global Data Centre Outlook 2026–50
- Reuters: AI’s race to transform the world before the money runs out
- Reuters: Dash for small gas turbines set to impact data center costs
- Amazon: Built Together data-center community commitments
Exploited vulnerabilities and security maintenance
- Raymond Tec: California Curbs Web-Tracking Suits, Plus 3 Stories
- Raymond Tec: FTC Opens AI-Agent Probe, Plus 3 Tech Stories
- Raymond Tec: Can AI Pay for Its Infrastructure? Plus 3 Stories
- Fortinet PSIRT: FG-IR-26-175 / CVE-2026-104286
- CISA: Known Exploited Vulnerabilities Catalog
- Cisco: Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- GitLab: AI Gateway critical patch release
AI voice fraud and exposed credentials
- Raymond Tec: AI Voice Scam Triggered €95M, Plus 4 Stories
- Reuters: AI messaging scam costs Intesa millions
- Truffle Security: GitHub repos exposed 543,699 credentials nobody revoked
- Microsoft: 2026 Digital Defense Report
AI agents, permissions and regulation
- Raymond Tec: FTC Opens AI-Agent Probe, Plus 3 Tech Stories
- Raymond Tec: Apple Tightens Mac Data Access, Plus 4 Stories
- Apple Developer: Updates to Full Disk Access in macOS
- Associated Press: FTC investigates AI developers over consumer risks
AI training and copyright
- Raymond Tec: AI Is Helping Price Your Big Mac, Plus 3 Stories
- U.S. Court of Appeals for the Third Circuit: Thomson Reuters v. Ross Intelligence opinion
- Reuters: Unsealed opinion explains Thomson Reuters’ AI fair-use win
Something Good: faster dementia diagnosis
Photo by Kevin Ache on Unsplash.
